Описание
Scripting Engine Memory Corruption Vulnerability
Меры по смягчению последствий
To address this vulnerability, a Throttling Policy for EWSMaxSubscriptions could be defined and applied to the organization with a value of zero. This will prevent the Exchange server from sending EWS notifications, and prevent client applications which rely upon EWS notifications from functioning normally. Examples of impacted applications include Outlook for Mac, Skype for Business, notification reliant LOB applications, and some iOS native mail clients.
Please see Throttling Policy, for more information.
An example:
New-ThrottlingPolicy -Name AllUsersEWSSubscriptionBlockPolicy -EwsMaxSubscriptions 0 -ThrottlingPolicyScope Organization
A planned update is in development. If you determine that your system is at high risk then you should evaluate the proposed workaround.
After installing the update, you can undo the above action with this command:
Remove-ThrottlingPolicy AllUsersEWSSubscriptionBlockPolicy
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems | ||
| Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems | ||
| Internet Explorer 11 on Windows 10 Version 1803 for ARM64-based Systems | ||
| Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems | ||
| Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems | ||
| Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems | ||
| Internet Explorer 11 on Windows Server 2019 | ||
| Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems | ||
| Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems | ||
| Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
7.5 High
CVSS3
Связанные уязвимости
Scripting Engine Memory Corruption Vulnerability
Уязвимость компонента Scripting Engine браузера Internet Explorer, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
EPSS
7.5 High
CVSS3